---
title: "Your car is collecting more data about you than you think"
subtitle: "Northeastern researchers tested 21 vehicles and companion apps for third-party data sharing"
slug: your-car-is-collecting-more-data-about-you-than-you-think
url: https://listedarticles.com/articles/your-car-is-collecting-more-data-about-you-than-you-think
canonical_url: https://news.northeastern.edu/2026/09/29/connected-car-privacy-violation-research/
content_type: research
language: en
published_at: 2026-09-29T00:00:00.000Z
updated_at: 2026-10-02T00:12:53.033Z
author: "Cesareo Contreras"
author_url: https://news.northeastern.edu/
authored_by: human
publisher: "Northeastern University"
publisher_url: https://news.northeastern.edu/
topics: ["Privacy", "Security", "Research", "Mobile"]
license: all-rights-reserved
word_count: 414
reading_minutes: 2
citation: "Cesareo Contreras, Northeastern University. \"Your car is collecting more data about you than you think.\" 29 Sept 2026. https://news.northeastern.edu/2026/09/29/connected-car-privacy-violation-research/ (all-rights-reserved)"
# The full text follows. The web page shows an extract and sends readers
# to the source above; quote the citation and link the canonical URL.
---

# Your car is collecting more data about you than you think

*Northeastern researchers tested 21 vehicles and companion apps for third-party data sharing*

> Northeastern cybersecurity researchers, with Consumer Reports, found connected cars and OEM apps sending VINs, location, and emails to advertising and analytics third parties—and call for clearer opt-in defaults.

# Your car is collecting more data about you than you think

Northeastern researchers tested 21 vehicles and their accompanying mobile apps to investigate what data manufacturers are collecting.

Major car manufacturers are sharing drivers' personal information with third-party companies and data brokers, new Northeastern University research shows.

As part of a partnership with Consumer Reports, privacy and cybersecurity professors at Northeastern tested 21 vehicles from 19 car brands. The investigation—covering vehicles and companion mobile apps—found companies sharing details such as Vehicle Identification Numbers (VIN), location data, and email addresses.

David Choffnes, a Northeastern cybersecurity professor and one of the report's authors, said the work followed reporting that General Motors collected data from cars and sold it to insurance companies. The team wanted a wider-scale analysis of cars on the road today.

## How they measured

Researchers rerouted internet traffic vehicles sent to networks they controlled. Vehicle payloads were often encrypted end-to-end, but app traffic could be decrypted on phones the researchers owned. From there they identified personal information flowing to third parties including Adobe Analytics, Axiom, and ContentSquare among the most contacted.

Manufacturers disclosed in privacy policies that they *may* share personal information with third parties, but typically do not name which parties or for what purpose.

"We have these companies that have nothing to do with car functionality that are getting information about you, what car you have, and sometimes also your GPS location," Choffnes said.

Such stable identifiers can enable cross-context tracking linking vehicle ownership to behavioral data and purchase history elsewhere.

## Industry response

Some automakers made changes when presented with the data. Honda asked Amplitude to delete location and VIN data and updated its app to stop sending geolocation to that advertising company. Honda said VIN and location shared with the company were never available for independent use or sale under contract, and that app use is voluntary.

General Motors said it is committed to keeping customer data secure and only discloses data to service providers under strict contract limits that prohibit selling, sharing, or using data for the providers' own purposes.

Choffnes argues automakers must be more transparent, and that regulators should require clearer disclosure of what happens to the data. Researchers also argue opting out should not brick core vehicle functionality, and that defaults should be opt-in.

The peer-reviewed paper—*Automatic Transmission: An Empirical Study of Data Privacy in the Connected Vehicle Ecosystem*—will be presented at ACM IMC 2026 (Oct 12–16, Karlsruhe).

*Original: [Northeastern Global News](https://news.northeastern.edu/2026/09/29/connected-car-privacy-violation-research/)*
